Skip to main content
Green Ports Toolkit

Practice

Enterprise Risk Management (ERM) Framework

GovernancePlanning and DevelopmentOperations

Aspect contributions

How this practice contributes to the green port aspects.

AspectRoleJustification
Risk ManagementCore-
Regulatory ComplianceSecondaryERM supports compliance with regulatory and disclosure requirements
Financing (Green & Sustainable)SecondaryERM frameworks support investor confidence and access to green financing
Climate AdaptationSecondaryClimate risks are a material component of port ERM frameworks

Summary

An enterprise risk management (ERM) framework provides a structured approach for port organizations to identify, assess, manage, and monitor risks across all port activities (ISO, 2018).

This may include, among others, a formal ERM system aligned with ISO 31000 principles, risk registers covering operational, environmental, financial, and security risks, defined risk appetite and tolerance levels, integration of risk management into strategic planning, and periodic risk reviews and updates.

For DMC ports, an ERM framework can improve preparedness for environmental and operational risks, support proactive decision making, reduce the likelihood of major incidents, and align with regulatory and investor expectations. The practice is scalable from simplified risk registers for smaller ports to sophisticated digital risk management systems for major container terminals.

Details

Enterprise risk management provides a systematic mechanism for identifying and managing the full range of risks facing a port organization. ISO 31000:2018, the international standard for risk management, establishes principles and guidelines applicable to all types of organizations and risk categories. The standard guides organizations to establish a risk management framework, conduct risk assessments (identification, analysis, evaluation), implement risk treatments, and monitor and review risk management effectiveness (ISO, 2018).

The scope of a port ERM framework typically encompasses, among others, operational risks (including equipment failures, vessel incidents, labor disruptions), environmental risks (including spills, pollution events, non-compliance), financial risks (including revenue volatility, currency exposure, tariff changes), security risks (including cyber threats, physical security incidents), safety risks (including workplace injuries, hazardous goods incidents), and strategic risks (including market competition, regulatory changes, technology disruption). Climate related risks, both physical and transition, are an emerging focus area (TCFD, 2017; IFRS Foundation, 2023).

An effective ERM framework includes defined risk appetite and tolerance statements approved by the board, specifying the level and types of risk the organization is willing to accept. Risk registers document identified risks with assessed likelihood, consequence, and control effectiveness, and are updated through regular review cycles. Risk treatments may include, for example, avoiding the risk, reducing the risk through controls, transferring the risk through insurance or contracting, or accepting the risk where residual risk is within tolerance.

For ports with multiple tenants and operators, ERM may need to address both port authority level risks and operator level risks. Integration of ERM with environmental management systems (ISO 14001), occupational health and safety management systems (ISO 45001), and business continuity management systems provides a consistent governance framework across management domains (ISO, 2026; ISO, 2018b).

In DMCs, ERM capacity varies considerably. Operators with terminals in DMCs, such as PSA International have implemented ERM frameworks and manage climate-related risks through a process aligned with the TCFD recommendations (PSA International, 2023). State owned port operators in Indonesia and Thailand are progressively formalizing ERM practices, often in response to national corporate governance standards and disclosure requirements. For smaller ports, simplified risk registers using standardized templates can establish a starting point, with digital systems introduced progressively.

Enabling factors

Policy Environment

ISO 31000:2018 risk management standard; national corporate governance codes; IFRS S1 and IFRS S2 sustainability disclosure standards; TCFD and TNFD recommendations.

Improved Technologies & Standards

Digital risk management platforms; risk register software; scenario analysis and modeling tools; climate data and projection platforms.

Sustainable Procurement

Risk assessment requirements in procurement and supplier contracts; inclusion of risk management in tenant agreements.

Partnerships & Collaboration

Industry associations such as IAPH; audit firms for independent risk assurance; regulatory engagement for risk disclosure standards.